upstream: adapt to RSA/SHA1 deprectation

OpenBSD-Regress-ID: 952397c39a22722880e4de9d1c50bb1a14f907bb
This commit is contained in:
djm@openbsd.org 2021-08-30 01:15:45 +00:00 committed by Damien Miller
parent 2344750250
commit 7db3e0a9e8

View File

@ -1,4 +1,4 @@
# $OpenBSD: knownhosts-command.sh,v 1.2 2020/12/22 06:47:24 djm Exp $ # $OpenBSD: knownhosts-command.sh,v 1.3 2021/08/30 01:15:45 djm Exp $
# Placed in the Public Domain. # Placed in the Public Domain.
tid="known hosts command " tid="known hosts command "
@ -39,7 +39,9 @@ chmod a+x $OBJ/knownhosts_command
${SSH} -F $OBJ/ssh_proxy x true && fail "ssh connect succeeded with bad exit" ${SSH} -F $OBJ/ssh_proxy x true && fail "ssh connect succeeded with bad exit"
for keytype in ${SSH_HOSTKEY_TYPES} ; do for keytype in ${SSH_HOSTKEY_TYPES} ; do
algs=$keytype
test "x$keytype" = "xssh-dss" && continue test "x$keytype" = "xssh-dss" && continue
test "x$keytype" = "xssh-rsa" && algs=ssh-rsa,rsa-sha2-256,rsa-sha2-512
verbose "keytype $keytype" verbose "keytype $keytype"
cat > $OBJ/knownhosts_command << _EOF cat > $OBJ/knownhosts_command << _EOF
#!/bin/sh #!/bin/sh
@ -48,6 +50,6 @@ test "x\$1" = "x$keytype" || die "wrong keytype \$1 (expected $keytype)"
test "x\$3" = "x$LOGNAME" || die "wrong username \$3 (expected $LOGNAME)" test "x\$3" = "x$LOGNAME" || die "wrong username \$3 (expected $LOGNAME)"
grep -- "\$1.*\$2" $OBJ/known_hosts grep -- "\$1.*\$2" $OBJ/known_hosts
_EOF _EOF
${SSH} -F $OBJ/ssh_proxy -oHostKeyAlgorithms=$keytype x true || ${SSH} -F $OBJ/ssh_proxy -oHostKeyAlgorithms=$algs x true ||
fail "ssh connect failed for keytype $x" fail "ssh connect failed for keytype $x"
done done